Security headers: five lines that close common attacks
HSTS, nosniff, framing protection and Referrer-Policy: what each header does and how to enable it on your server.
Checked against sources: 30 September 2026

- 5headers close common attacks
- 180 daysHSTS minimum for Awe Check
- 1 yeartypical HSTS period
Five headers
- Strict-Transport-Security tells browsers to always use HTTPS, even when http:// was typed.
- X-Content-Type-Options: nosniff stops the browser from guessing a file type.
- X-Frame-Options or frame-ancestors keeps your site out of another page’s frame.
- Referrer-Policy stops full page URLs leaking to other sites.
- A hidden server version: a version number in headers tells attackers which vulnerabilities to try.
A ready set
In nginx that is the add_header directive and server_tokens off, in Apache Header always set and ServerTokens Prod. Hosting panels and Cloudflare have toggles for the same values.
Strict-Transport-Security: max-age=31536000; includeSubDomains X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN Referrer-Policy: strict-origin-when-cross-origin
Be careful with HSTS
First make sure every subdomain works over HTTPS and start with a short period: max-age=300. After a week set a year. Awe Check asks for at least 180 days.
Frequently asked
Do I also need a CSP?
It is stronger but harder: a wrong CSP breaks the site. Start with the five headers above and add CSP separately, checking the console.
Do headers affect SEO?
Not directly. But HTTPS and a stable, uncompromised site are part of the trust search engines build on.
